Why Zero-Knowledge Proofs Fail as Age Verification Solutions
Zero-Knowledge Proofs (ZKPs) are not the privacy-preserving silver bullet for age verification laws. Recent tests reveal vulnerabilities and centralization risks.

Age verification laws, which require websites and online platforms to confirm or estimate a user's age, are proliferating across the United States and other regions. Currently, about half of U.S. states have implemented such laws, while federal proposals like the KIDS Act and the Kids Online Safety Act (KOSA) are gaining traction. The European Union is moving toward a centralized age verification system via a mini-wallet app within the European Digital Identity (EUDI) Wallet, slated for full deployment by 2026. Australia has also enacted broad restrictions on minors' internet access.
Many age verification systems fail to achieve their primary goal of restricting minors' access while posing significant privacy risks. Some advocates of stricter online controls have promoted Zero-Knowledge Proofs (ZKPs) as a potential solution. However, recent developments indicate that ZKP-based age verification systems are vulnerable to manipulation, hacking, and other flaws, undermining their effectiveness and safety.
ZKPs and the Risks of Centralized Control
Zero-Knowledge Proofs are cryptographic methods that allow one party to prove the validity of a statement without revealing the underlying data. In age verification, a user would receive a token proving their age, which could then be verified by websites without exposing personal details. While this concept is mathematically robust, its application in age verification introduces serious concerns.
A key issue is the centralization of power. ZKP-based systems require a trusted issuer of age verification tokens, creating a single point of failure that could be exploited by governments or bad actors. Authoritarian regimes could pressure issuers to revoke access for targeted individuals, effectively cutting them off from the internet. Additionally, the issuer could track users' online activities through metadata, compromising privacy on a massive scale.
Real-World Failures of ZKP-Based Age Verification
Testing of ZKP systems has revealed critical vulnerabilities. In the European Union, the mini-wallet app within the EUDI Wallet is being rolled out with promises of secure age verification. However, a security researcher demonstrated that a simple Chrome extension could bypass the system by repeatedly reusing an "over-18" token without requiring fresh verification. This flaw highlights the ease with which such systems can be circumvented.
More than 400 security researchers have warned that age verification systems, even those designed with privacy in mind, pose significant risks. Centralized identity verification creates a prime target for cyberattacks and government overreach. Once fully integrated into the EUDI Wallet, these systems could expose not just age data but also sensitive information like passports, driver’s licenses, travel records, and financial data.
The Limitations of ZKPs in Age Verification
Despite their technical sophistication, ZKPs do not address the fundamental problems of age verification. No existing method can guarantee accuracy, universal coverage, and privacy protection without introducing severe security risks. ZKPs may shift the burden of trust but do not eliminate the core issues—technical complexity, susceptibility to exploitation, and the erosion of digital rights.
Lawmakers must recognize that ZKPs are not a panacea for age verification challenges. Mandatory online age verification remains a flawed and dangerous approach, one that undermines privacy and internet freedom. The Electronic Frontier Foundation (EFF) urges policymakers to reconsider these measures and prioritize solutions that protect users' rights without imposing unnecessary risks.
Comments (0)
No comments yet — be the first to weigh in.
Related Coverage
Technology
Mozilla CTO Calls for Open AI Infrastructure to Match Internet’s Open Model
Mozilla’s CTO Raffi Krikorian urges treating AI as infrastructure, highlights the narrowing performance gap with open‑source models like Qwen, and calls for policy support to empower businesses and governments to adopt open‑weight AI for cost, control and privacy.
Technology
DIY Robotic SD Card Library Maximizes Existing Components, Saves Costs
A maker builds a robotic microSD card library using a 3D-printed arm and rack-and-pinion gripper to automate card handling, saving costs amid rising component prices.
Technology
EFF Champions Digital Rights at Las Vegas Security Conferences
Discover how the Electronic Frontier Foundation (EFF) fights for privacy and free expression at major tech security events like DEF CON, Black Hat, and BSides Las Vegas.
Technology
Developers Warned About Hidden Location Privacy Risks in Ad SDKs
EFF report reveals how advertising SDKs in apps automatically share users' location data with brokers, risking privacy violations and misuse in investigations.
Most Read
The Rise of 'Big Security': How Global Politics Prioritizes Control Over Solutions
UK Supplies Ukraine with Storm Shadow Missile Blueprints: A Strategic Shift
US Expands Iran Sanctions: China Vows Response as Tensions Rise